Do AI vendors keep my data?
Claim Raven may send the text, files, images, and account context needed for an AI feature to contracted commercial AI providers. The current Privacy Policy identifies the providers and current routing boundaries; commercial API terms do not use inputs and outputs for foundation-model training by default unless a customer opts in. Standard abuse-monitoring retention is commonly up to 30 days, but limited content may be retained longer for safety-policy enforcement or legal obligations, and settings can differ by provider, account, and feature. Claim Raven applies best-effort masking only on supported text paths, so raw PDFs, images, and OCR can require sending an unredacted visual input. It does not share account data with advertising vendors or data brokers.
Overview
Up to 30 days is not a universal deletion promise Provider terms can differ by endpoint, model, account setting, safety rule, legal obligation, and negotiated configuration. Some provider features retain application state until it is deleted, and some designated models or safety investigations can require different retention. Claim Raven does not promise that every request has zero data retention.
What Claim Raven sends
Requested content: An AI feature may send the prompt, relevant chat context, extracted text, a file, image, screenshot, or scanned PDF page needed to perform the task you requested. Account context when authorized: Consent-dependent features may include relevant VA profile or claim context when AI Data Consent is enabled. The active Ask Raven conversation still needs its own messages and files to work even when cross-conversation or VA-profile personalization is off. Private-document routing: The current Privacy Policy says uploaded DD214s, VA letters, military documents, resume images, and resume text use Claim Raven's tracked Anthropic commercial API path and are not sent to xAI. Providers and routing can change as capabilities and contracts change, so the Privacy Policy is the current source of truth. Public-source routing: Current xAI use is limited to app-initiated analysis of public BVA decisions and regulatory or manual text. Do not assume public legal-research processing and private veteran-document processing have the same provider or data rule.
What the provider terms do and do not mean
Training: Current commercial API terms for the providers named in the Privacy Policy do not use API inputs and outputs to train foundation models by default unless the customer affirmatively opts in. That is a default commercial term, not a promise that provider terms can never change. Safety and abuse monitoring: Standard provider retention is commonly up to 30 days. A provider may retain limited content longer for safety-policy enforcement, legal obligations, or another documented exception. Endpoint, model, and account differences: Zero-data-retention or modified-monitoring programs require provider eligibility and configuration. Stateful endpoints, stored files, application objects, designated covered models, and negotiated terms can follow different rules. A request option such as store false is not proof that every provider copy or safety log is immediately deleted. Claim Raven use: Claim Raven does not use VA data, claim information, uploaded records, or AI content for advertising, marketing profiles, or sale. Contracted providers receive only the content needed for the requested service and remain subject to their applicable terms and Claim Raven instructions.
Masking has an important visual-file limit
Claim Raven applies best-effort masking to common direct identifiers on supported text paths. It cannot reliably remove text or identifiers from an image or scanned PDF before a vision or OCR provider reads the visual input. That means a raw image, screenshot, or scanned page may reach the contracted provider unredacted. Masking also is not guaranteed to catch every identifier or medical detail.
Use the control that matches your goal
Share only what the task needs Remove unrelated pages and redact unnecessary identifiers before uploading when doing so will not undermine the task. Do not submit another person's records unless you have permission or other legal authority. Control future consent-dependent AI use Use AI Data Consent in Settings. Turning it off affects future consent-dependent access to VA profile, claim, cross-conversation, and cross-tool context; it does not erase the active chat's own messages or files and does not undo prior lawful processing. Delete a saved Claim Raven artifact Use the feature's control to remove a conversation, attachment, report, analysis, or other saved item. Deleting a Claim Raven record does not prove that a provider's safety log, legal hold, or backup copy was deleted at the same moment. Request broader deletion Use the verified account-deletion or consumer-health-data request process when appropriate. Claim Raven will notify relevant processors of a valid covered request, while provider and backup deletion can take longer where their terms or law permit. Check the current policy before sensitive use Provider lists, models, endpoints, routing, retention programs, and contractual controls can change. Review the current Privacy Policy and the notice shown by the feature before sending material you consider especially sensitive.
Current privacy and provider sources
Current privacy and provider sources Claim Raven Privacy Policy https://claimraven.com/privacy-policy Claim Raven Security and Privacy https://claimraven.com/security Anthropic Privacy Center: API data retention https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data Anthropic Privacy Center: Covered Model retention practices https://privacy.claude.com/en/articles/15425996-data-retention-practices-for-covered-models OpenAI API data controls and retention by endpoint https://developers.openai.com/api/docs/guides/your-data#default-usage-policies-by-endpoint xAI API security and data privacy FAQ https://docs.x.ai/developers/faq/security
Related privacy guidance
Related privacy guidance Review current AI providers and routing /privacy-policy#third-party-sharing Review AI Data Consent /privacy-policy#ai-data-consent See Claim Raven security controls /security Learn where Claim Raven stores data /help-center/privacy-and-security/faq-where-is-data-stored Keep files and support requests safer /help-center/privacy-and-security/feature-data-protection Learn how account deletion works /help-center/privacy-and-security/faq-delete-account
More information
Review the current AI-provider policy Open the Privacy Policy for the current provider list, routing boundaries, consent rules, and material retention qualifications. Open the Privacy Policy /privacy-policy#third-party-sharing